[Japanese]
|
JVNDB-2013-000024
|
Multiple NEC mobile routers vulnerable to cross-site request forgery
|
Multiple mobile routers provided by NEC contain a cross-site request forgery vulnerability.
Multiple mobile routers provided by NEC contain a vulnerability in web-based management utility, which may result in a cross-site request forgery.
Sen UENO of Tricorder Co. Ltd., Hiroshi Kumagai and Kimura Youichi reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 4.0 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: High
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: Partial
|
|
NEC Corporation
- Aterm WM3450RN
- Aterm WM3600R
- Aterm WR8160N
- Aterm WR8170N
- Aterm WR8370N
- Aterm WR8600N
- Aterm WR8700N
- Aterm WR9500N
|
A wide range of products are affected.
For more information, refer to the information provided by the developer.
|
If a user views a malicious page while logged in, settings of the product may be initialized, or the product may be rebooted.
|
[Update the Software]
Update to the latest version of the firmware provided by the developer.
[Apply a workaround]
The following workaround, for products which have no revised firmware, may mitigate the affects of this vulnerability.
* Close the web browser when finished setting in web-based management utility, and delete Basic Authentication information immediately.
For more information, refer to the information provided by the developer.
|
NEC Corporation
- NEC Security Information : NV13-005 (Japanese Only)
|
- Cross-Site Request Forgery(CWE-352) [IPA Evaluation]
|
- CVE-2013-0717
|
- JVN : JVN#59503133
- National Vulnerability Database (NVD) : CVE-2013-0717
|
- [2013/03/19]
Web page was published
[2013/06/25]
References : Content was added
|